alerting

package
v0.2.4 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 28, 2026 License: Apache-2.0 Imports: 10 Imported by: 0

Documentation

Overview

Package alerting turns platform events a defender must act on into delivered notifications. It applies the tenant's alert rule, hands each qualifying alert to every configured sink, and audits the outcome per sink, so a missed page is visible in the audit log rather than silent. Delivery is best effort by design: the event that produced the alert (an incident, a finding) is already durable, and a failing webhook must never roll it back or block the pipeline that produced it.

Index

Constants

This section is empty.

Variables

View Source
var ErrNoSinkAcknowledged = errors.New("no alert sink acknowledged the test alert")

ErrNoSinkAcknowledged is returned by Test when every configured sink refused the test alert.

Functions

This section is empty.

Types

type Outcome

type Outcome struct {
	Matched     bool `json:"matched"`
	Delivered   int  `json:"delivered"`
	Failed      int  `json:"failed"`
	AuditFailed int  `json:"audit_failed,omitempty"`
}

Outcome counts what one notification did across sinks. Matched is false when the rule filtered the alert out; then nothing was attempted.

type Service

type Service struct {
	// contains filtered or unexported fields
}

Service evaluates and delivers alerts.

func NewService

func NewService(sinks []ports.AlertSink, rule alerting.Rule, audit ports.AuditLogger, clock ports.Clock, ids ports.IDGenerator) (*Service, error)

NewService validates its dependencies. At least one sink is required: a service with nowhere to deliver is a misconfiguration the composition root should refuse, not a silent no-op.

func (*Service) Close

func (s *Service) Close()

Close stops accepting asynchronous notifications and waits for the queued ones to finish.

func (*Service) Flush

func (s *Service) Flush()

Flush blocks until every notification queued so far has been delivered. Tests use it; a caller in production never waits on delivery.

func (*Service) IncidentsCreated

func (s *Service) IncidentsCreated(ctx context.Context, actor string, engagementID shared.ID, created []incident.Incident)

IncidentsCreated notifies each incident correlation opened. It satisfies correlationuc.IncidentNotifier and returns nothing on purpose: the incidents are recorded, and the per-sink result is in the audit log. Delivery runs on the worker set, detached from the caller's request context, so a slow or dead receiver never holds the agent's ingest; the rate limit and a full queue are audited, never silent.

func (*Service) Notify

func (s *Service) Notify(ctx context.Context, actor string, a alerting.Alert) Outcome

Notify applies the rule and delivers to every sink, auditing each attempt. The alert must validate; an invalid alert is a programming error on the producer side and is audited as such.

func (*Service) Test

func (s *Service) Test(ctx context.Context, actor string) (Outcome, error)

Test delivers a synthetic alert so an operator can prove the configured sinks receive alerts. It bypasses the severity rule and reports the outcome; an error means no sink acknowledged it.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL